Joomla! Developer Network

[20081101] - Core - com_content XSS vulnerability

Project: Joomla!

SubProject: com_content

Severity:moderate

Versions: 1.5.7 and all previous 1.5 releases

Exploit type: XSS

Reported Date: 2008-October-03

Fixed Date: 2008-November-10

Description

The defaults on com_content article submission allow entry of dangerous HTML tags (script, etc). This only affects users with access level Author or higher, and only if you have not set filtering options in com_content configuration.